kevmap

TechniquesT1606.002 › AN0422

AN0422 Analytic 0422

Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Forged SAML tokens may be leveraged to access O365 apps such as Outlook or SharePoint. Defenders should monitor for token replay across multiple clients or access attempts to privileged mailboxes without prior interactive login.</p>
Detects
T1606.002 SAML Tokens
Part of
DET0148 Detection Strategy for Forged SAML Tokens

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:exchangeMailbox access using SAML token without corresponding MFA eventDC0007 Web Credential Usage
m365:sharepointFile access with forged or anomalous SAML claimsDC0067 Logon Session Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ReplayDetectionThresholdNumber of times a token is reused within short timeframe.